Privacy Policy
Last updated: April 2026
1. Who We Are
TripoSIM is operated by BroadNet Technologies LLC, headquartered in New Jersey, USA. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our website (triposim.com) and services.
TripoSIM is operated by BroadNet Technologies LLC, a company registered in Dubai, United Arab Emirates ("TripoSIM", "we", "us", or "our"). This Privacy Policy explains in detail what information we collect, why we collect it, how we use and share it, how long we keep it, how we protect it, and the rights and choices you have. It applies to our website (triposim.com), our mobile applications, and all related services (together, the "Services"). By using the Services you agree to the practices described here.
Information We Collect
We collect the following categories of information, and only what we need to provide and improve the Services:
- Account information — your name, email address, and (optionally) phone number, plus a securely hashed password, created when you register.
- Order and transaction information — the eSIM plans you purchase, order history, destination and validity, and the ICCID of the eSIM profile issued to you.
- Payment information — payments are processed by our PCI-DSS-compliant payment processor (Stripe), which receives your card details directly. We never see or store your full card number; we retain only a payment reference, the amount, currency, and status.
- Device and technical information — IP address, browser type, operating system, device model, language, and, for our mobile apps, push-notification tokens and a device identifier used to deliver notifications.
- Usage and analytics information — pages viewed, features used, referring source, and interactions, collected (only with your cookie consent) to understand and improve the Services.
- Location information — collected only with your explicit permission (for optional features such as the WiFi map); if you decline, the Services work normally without it.
- Communications and support — the contents of messages you send us (email, chat, support tickets) so we can respond and keep a record of the request.
How We Use Your Information
We use the information above for the following purposes:
- To provide the Services — create your account, process your order, provision your eSIM, deliver the QR code, and provide customer support.
- To process payments and prevent fraud, and to keep records required for tax, accounting, and legal compliance.
- To operate, secure, and improve the Services, diagnose problems, and develop new features.
- To communicate with you about your orders, account, and service updates, and — only if you opt in — marketing messages you can unsubscribe from at any time.
- To measure our own marketing (for example, website conversions and advertising performance) where you have given cookie consent.
- To comply with legal obligations and enforce our terms.
Legal Bases for Processing
Where the GDPR or similar laws apply, we rely on these legal bases: performance of our contract with you (to deliver the Services you buy); your consent (for optional cookies, location, and marketing, which you can withdraw at any time); our legitimate interests (to secure and improve the Services and prevent fraud, balanced against your rights); and compliance with legal obligations (such as tax and record-keeping).
How We Share Information
We do not sell your personal information. We share it only as needed to run the Services:
- Connectivity partners — to activate your eSIM we share the minimum data required (your plan selection and the eSIM ICCID) with the network partner that fulfils your order.
- Service providers — payment processing, cloud hosting, email and SMS delivery, push notifications, analytics, and security, each acting on our instructions under contract.
- Legal and safety — where required by law, court order, or to protect the rights, safety, and security of our users, the public, or TripoSIM.
- Business transfers — if TripoSIM is involved in a merger, acquisition, or asset sale, information may be transferred, subject to this Policy.
Data Retention
We keep personal information only as long as necessary for the purposes above. Account information is kept while your account is active. Order and payment records are retained for up to 7 years to meet tax and accounting obligations, after which they are deleted or anonymized. Analytics data is retained on a rolling basis. When you delete your account, we remove your personal information as described in the Account Deletion section below, except where longer retention is required by law.
How We Protect Your Data
We use industry-standard safeguards to protect your information, including encryption in transit (HTTPS/TLS), hashed passwords, access controls that limit who can see personal data, network firewalls, and monitoring. No method of transmission or storage is completely secure, but we work continuously to protect your information and to notify you and the authorities of any breach as required by law.
Your Privacy Rights and Choices
Depending on where you live, you may have the right to: access the personal information we hold about you; correct inaccurate information; delete your information; receive a copy in a portable format; object to or restrict certain processing; and withdraw consent at any time (without affecting processing already carried out). You also have the right to lodge a complaint with your local data-protection authority.
To exercise any of these rights, email [email protected] or use Settings → Delete Account in the app or website. We will respond within the time required by applicable law. You can opt out of marketing at any time via the unsubscribe link, and you can manage cookies through our cookie banner.
International Data Transfers
TripoSIM operates globally, and your information may be processed in countries other than your own, including the United Arab Emirates and countries where our service providers operate. Where we transfer personal data across borders, we use appropriate safeguards (such as standard contractual clauses) to ensure it remains protected in line with this Policy.
Cookies and Similar Technologies
We use strictly necessary cookies to run the site (for example, to keep you logged in and secure), and — only after you accept our cookie banner — analytics and advertising cookies to measure and improve the Services. Advertising and analytics storage default to "denied" under Google Consent Mode v2 and are enabled only after you accept. You can change or withdraw your choice at any time, and declining optional cookies does not affect your ability to buy or use an eSIM.
2. Information We Collect
We collect the following types of information:
- Account information: Name, email address, and password when you create an account.
- Payment information: Processed securely by Stripe. We do not store full card numbers — only the last four digits, card brand, and expiration for your reference.
- Usage data: eSIM data consumption and status, used to display your dashboard and monitor service quality.
- Technical data: IP address, browser type, device information, and pages visited for security and analytics.
- Communications: Messages you send to our support team.
Mobile Application Data
When you use the TripoSIM mobile application (Android or iOS), we may additionally collect:
- Push notification tokens (FCM for Android, APNs for iOS) — used exclusively to deliver incoming call alerts and service notifications. Tokens are stored on our server and removed when you log out.
- SIP/VoIP credentials — generated server-side for HomeLink call forwarding. Stored securely on-device (Android SharedPreferences, iOS Keychain) and on our server. Never shared with third parties.
- Phone contacts (HomeLink feature only) — if you enable HomeLink and grant permission, we sync your contact names and phone numbers (normalized to E.164 format) to our server. This data is used solely to route incoming calls to the correct subscriber. Contact sync is completely optional and can be disabled at any time in Settings. Contacts are deleted from our server when you disable the feature or delete your account.
- Device identifiers — device model, OS version, and a vendor-assigned device ID for push notification delivery and debugging.
HomeLink (VoIP Call Forwarding)
HomeLink allows you to receive calls to your home phone number on the TripoSIM app over data. When you activate HomeLink:
- We assign you a virtual DID phone number and store your SIP registration credentials.
- Call detail records (caller number, call duration, timestamp) are logged for your call history and billing purposes.
- Voice calls are transmitted over encrypted SIP/UDP protocol. Audio is processed in real-time and is NOT recorded or stored.
- If you enable contact sync, caller names are matched locally on our routing server to deliver calls without delay.
TripoSIM Shield & Parental Controls
Shield provides DNS-level ad blocking and content filtering. Parental Controls extend this with child-safety filtering (Kids Safe / Teen Friendly modes).
- DNS queries are routed through our secure DNS proxy server (shield.triposim.com) which forwards to upstream filtering providers (CleanBrowsing). We do NOT log individual DNS queries or browsing history.
- Parental control settings (filter level, PIN hash) are stored in our database associated with your user account.
- The PIN is stored as a bcrypt hash and cannot be reversed. We cannot recover your PIN.
- No browsing activity data is collected, stored, or shared with any third party.
Location Data
We collect location data only with your explicit consent:
- WiFi Map feature — if you grant location permission and accept cookies, we use your coordinates to show nearby WiFi hotspots. Location is sent to our server and to Google Places API for hotspot lookup.
- IP-based geolocation — only when you have accepted cookie consent, we may use your IP address to detect your country for currency display and emergency number lookup. This uses the ipapi.co service.
- If you decline cookies or deny location permission, NO location data is collected. The app functions normally without location access.
Third-Party Services
We use the following third-party services that may process your data:
- Stripe (stripe.com) — payment processing. Stripe receives your payment card details directly. We never see or store full card numbers.
- Google Analytics — website analytics, loaded ONLY after you accept cookie consent. Tracks page views and user behavior anonymously.
- Firebase Cloud Messaging — push notification delivery for Android devices.
- Apple Push Notification service (APNs) — push notification delivery for iOS devices.
- CleanBrowsing — upstream DNS filtering for Shield and Parental Controls. DNS queries are forwarded but not logged by our proxy.
- Cloudflare Turnstile — CAPTCHA verification during login and registration to prevent automated attacks.
- eSIM Vendors — we share your plan selection and ICCID with the vendor that fulfills your eSIM order. Vendor selection is automatic via our routing engine.
Google API Services & Advertising Data
TripoSIM uses Google advertising and measurement services to run and measure our own marketing. As required by the Google API Services User Data Policy, this section explains how we handle data in connection with Google services and APIs.
- Measurement & advertising tags: With your cookie consent, we load Google’s tag (gtag.js) to measure website conversions and build remarketing audiences. Under Google Consent Mode v2, advertising and analytics storage default to "denied" and are enabled only after you accept cookies. If you decline, no Google advertising or analytics cookies are set.
- Google Ads API (our own account only): We operate an internal, server-side integration that manages TripoSIM’s own Google Ads advertising account using our own authorized credentials. This integration accesses only our own advertising account. It does NOT access, collect, store, or share any personal data from the Google accounts of our website visitors or customers.
- Limited Use: TripoSIM’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not sell Google API data, do not use it for personalized advertising, and do not allow humans to read it except where permitted by that policy or with your explicit consent.
- Data retention: aggregate advertising performance data (such as campaign clicks and conversions for our own account) may be cached on our servers for reporting. It contains no personal data about our visitors.
For questions about our use of Google services, contact [email protected].
3. How We Use Your Information
- To provide, maintain, and improve our services
- To process your orders and deliver eSIM profiles
- To communicate order confirmations, usage alerts, and support responses
- To detect and prevent fraud and unauthorized access
- To comply with legal obligations
4. Information Sharing
We do not sell your personal information. We share data only with:
- eSIM vendors: To provision and manage your eSIM (ICCID and plan details only).
- Payment processors: Stripe, to process your payments securely.
- Legal authorities: When required by law or to protect our rights.
5. Data Security
We use industry-standard security measures including SSL/TLS encryption, password hashing (bcrypt), and secure server infrastructure. However, no method of electronic transmission is 100% secure, and we cannot guarantee absolute security.
6. Data Retention
We retain your account information for as long as your account is active. Order and transaction records are retained for up to 7 years for legal and accounting purposes. You may request deletion of your account and personal data at any time.
7. Your Rights
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your personal data
- Withdraw consent for marketing communications
- Request a copy of your data in a portable format
To exercise these rights, contact us at [email protected].
8. GDPR and International Users
If you are located in the European Economic Area (EEA), United Kingdom, or other jurisdictions with data protection laws, you have additional rights under the General Data Protection Regulation (GDPR) or equivalent legislation. These include the right to access, rectification, erasure, restriction of processing, data portability, and the right to object.
For GDPR-related inquiries or to exercise your rights, contact our Data Protection Officer at [email protected].
9. Cookies
We use essential cookies to maintain your login session and preferences. We may use analytics cookies (Google Analytics) to understand how visitors interact with our website. By continuing to use our website, you consent to the use of essential cookies. You can control cookie settings through your browser. For full details, see our cookie preferences in your browser settings.
Account Deletion
You can delete your account at any time from Settings → Delete Account in the TripoSIM app or website. When you delete your account:
- Your personal information (name, email, phone) is permanently deleted.
- Your SIP credentials, push tokens, and contact sync data are removed.
- Your HomeLink number is released and call forwarding stops.
- Order and payment records are retained for 7 years as required by law, but are anonymized.
- Active eSIM profiles may continue to function until their validity expires, but are disassociated from your account.
Account deletion is irreversible. You will receive a verification code via email before deletion is confirmed.
Children's Privacy
TripoSIM is not directed at children under 13. We do not knowingly collect personal information from children under 13. The Parental Controls feature is designed for parents to manage their children's internet access — it does not require children to create accounts or provide personal information. If you believe a child has provided us with personal data, contact us to request deletion.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of significant changes via email.
11. Contact
For privacy-related inquiries: [email protected]
BroadNet Technologies LLC
New Jersey, United States